ISO 27001:2022 Transition: What exactly is changing and how you can follow suit
The transition from ISO/IEC 27001:2013 to 27001:2022 runs until October 2026. This article explains the structural changes, the eleven new controls and the operational consequences for ISB, risk management and audit planning.
With the publication of ISO/IEC 27001:2022 in October 2022, ISO has fundamentally restructured Annex A. According to the IAF resolution, the transition period ends on October 31, 2026. Anyone who has not switched to the new version by then will lose their certification. Essentially there are 93 controls instead of 114, four instead of fourteen topic areas and eleven new controls that were not explicitly required before. However, the underlying main standard (clauses 4 to 10) was only marginally adjusted, with the focus on clause 6.3 (planned changes). For existing customers with a valid certificate, this means: The transition audit is often linked to the next monitoring or recertification date.
This article focuses on the delta between 2013 and 2022 and on the question of what this means for the day-to-day business of the ISB, for the list of target measures (Statement of Applicability, SoA) and for the effort in the internal and external audit. You get an overview of which controls are new, which ones have been merged, how the transition planning with the certifier works and where the platform view noticeably reduces the effort. Others run compliance like a filing cabinet. We run it like software. At the end there is an assessment of which model will make the transition most reliable.
Key Takeaways
- ISO/IEC 27001:2022 reduces Annex A to 93 controls in four subject groups, of which eleven controls are completely new.
- The transition period ends on October 31, 2026; the ISMS transition typically requires six to nine months' notice, including a round of internal audits.
- The effort is significantly reduced if SoA, risk registers, measures and evidence are kept in a single versioned file structure.
Structural change: From the 14 to the 4 topic model
The most noticeable change is the reorganization of Annex A. Instead of fourteen sections (A.5 to A.18), there are now four topic groups: organisational controls (A.5), person-related controls (A.6), physical controls (A.7) and technological controls (A.8). This four-topic logic is based on ISO/IEC 27002:2022, which was restructured at the same time as a guide for the implementation of the controls. The old sections have been merged into the four groups, some controls have been summarized and others have been made more precise. This makes the structure easier to manage because topics such as access, data or supplier relationships are no longer scattered across several sections.
Specifically, Annex A:2022 now contains 93 controls. Compared to the previous version with 114 controls, this represents a noticeable consolidation, but no relief. The contents of the combined controls are retained, they are just structured more compactly. Anyone who translates an existing Statement of Applicability (SoA) must create a mapping table from the old to the new Annex, with justification for each control status (applicable or not applicable). This is mandatory, not optional: Without a comprehensible mapping justification, the auditor will ask questions about each individual control.
In addition, there are attribute classifications that ISO/IEC 27002:2022 introduces: control type (preventive, detective, corrective), information security objective (confidentiality, integrity, availability), cybersecurity concepts (Identify, Protect, Detect, Respond, Recover), operational capabilities and security domains. These attributes are not a certification requirement, but help structure the SoA and tagging logic in the workspace. The application of the controls counts for auditability, not the attribute schema. The appointed information security officer decides to what depth the attributes are used. In smaller organisations the standard tagging logic is sufficient, in larger corporations the full attribute model is worthwhile for reporting to management.
The eleven new controls at a glance
Eleven controls are completely new in ISO/IEC 27001:2022. They reflect the evolution of the threat situation since 2013 and the increasing importance of cloud, data flows and resilience. The list includes: A.5.7 Threat Intelligence, A.5.23 Information Security for Use of Cloud Services, A.5.30 ICT Readiness for Business Continuity, A.7.4 Physical Security Monitoring, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention, A.8.16 Monitoring Activities, A.8.23 Web Filtering and A.8.28 Secure coding. Each of these controls requires a policy, accountability and proof of effectiveness over the reporting year.
Three of these controls are particularly relevant to effort: A.5.7 Threat Intelligence requires a structured collection and evaluation of threat information, which requires a source list, an evaluation rhythm and a connection to risk management according to clause 6.1.2. A.5.23 Information Security for Use of Cloud Services requires guidelines for selection, use and termination of cloud services, including exit strategy. A.8.28 Secure Coding requires defined security coding standards, training and code reviews, which is particularly relevant for testing for software developing organisations.
The remaining eight controls have actually already been implemented in many companies, such as Configuration Management (A.8.9) or Data Leakage Prevention (A.8.12). This is less about setting up new measures and more about clearly documenting the existing status. Audit-proof, documented, § ISO-proof: The auditor calls, the evidence is ready. Anyone who uses the workspace creates an action sheet for each new control with the person responsible, frequency, control and reference to the risk register. The link to the incident process is particularly relevant to the audit for A.8.16 Monitoring Activities and A.5.7 Threat Intelligence because the bridge between sensors and responsiveness is observed here. Anyone who links the incident process with tickets or ITSM documents response times automatically.
Changes in the main standard (clauses 4 to 10)
The main standard of ISO/IEC 27001:2022 is almost identical to the 2013 version. The most important addition is found in clause 6.3 Planning Changes. This explicitly requires that changes to the ISMS must be made in a planned manner, with purpose, consequences, available resources, allocation of responsibilities and attention to risk assessment. What was previously implicit is now relevant for testing: Change requests in the ISMS are documented with their justification and approval. The audit specifically asks for a sample of changes from the previous year, including an assessment of the impact on risk.
Further minor adjustments concern clause 9.3 (management review), which now explicitly includes the topics that management must assess, as well as more precise wording in clause 7.5 on documented information. In practice, these changes are of an editorial nature and do not fundamentally change the audit logic. An existing ISMS based on 27001:2013 can be translated to 2022 with manageable effort if the documentation is maintained. On the other hand, anyone who had difficulty certifying in 2013 should use the transition as an opportunity to structurally clean up the ISMS. An existing improvement plan from the last management review can often be transferred directly into the transition phase.
More important than the clause adjustments is the consistent connection between the main standard and Annex A. The Statement of Applicability now not only refers to the 93 controls, but must justify the selection with reference to the risk assessment. Anyone who marks several controls as not applicable in the SoA should record the reasons in the risk register, not just as a footnote in the SoA. The appointment certificate, signed, filed, verifiable also applies to the responsibility of the top management approval of the SoA.
Transition plan: 6 to 9 months, three phases
Practice shows three phases. Phase 1 (Months 1 to 2): Delta analysis and gap identification. A mapping table from 27001:2013 to 27001:2022 is created and the existing controls are mirrored to the new structure. The eleven new controls are evaluated: actually new or already implemented but not yet documented. The result is a prioritised list of measures with resource estimates and those responsible. In this phase, management receives an initial effort estimate as a basis for decision-making.
Phase 2 (months 3 to 6): Implementation. New guidelines are being written, for example for threat intelligence, cloud usage, secure coding. Existing guidelines are updated, the risk register is related to the new controls, and the SoA is recreated. Training for ISB, IT management and critical roles is carried out. In this phase, the integration with the data protection function is important because many new controls (such as data masking, information deletion, data leakage prevention) have points of contact with Art. 32 GDPR.
Phase 3 (months 7 to 9): Internal audit, correction, certification audit. The internal audit checks the effectiveness of the new controls and identified deviations are corrected. The certification body carries out the transition audit, often combined with a surveillance audit or recertification. Anyone who integrates the transition into the audit cycle saves a separate appointment. The CIVAC SLA for the ISB order is two working days, in the classic market two to six weeks are common, which can put time pressure on the transition plan. Anyone who only approaches the order after phase 1 runs the risk of losing the time window for internal audits. Experience has shown that the certification body's Stage 1 and Stage 2 dates are in high demand in the second half of 2026.
Rethinking statements of applicability and risk assessment
The Statement of Applicability is the central document in the certification audit. In the new version it contains 93 lines, each with status (applicable or not), implementation status, reference to measure and reference to the risk. The temptation to keep the SoA as a pure table is great, but it is wrong and expensive to audit. Each entry must be linked to the risk register so that the auditor can understand the logic: why Control X is applicable, what risk does it address, what level of risk remains after application.
The risk assessment itself remains structurally unchanged: identification, analysis, assessment, treatment. What is new is that the risk treatment explicitly refers to the 93 controls. A risk such as unauthorized access to personal data is typically addressed with several controls, such as A.5.15 Access Control, A.8.3 Information Access Restriction, A.8.12 Data Leakage Prevention. In the SoA, all three are marked as applicable and linked to the risk. This multiple link must be explained in the audit and should be kept in the workspace with clear references.
Anyone who keeps the SoA and the risk assessment in two separate Excel files is vulnerable in the audit because the consistency has to be checked manually. In the CIVAC workspace, SoA and risk register are linked modules: A change in risk propagates into the SoA, a change in control propagates into the risk. This creates an audit-proof file situation without Excel copies, without version chaos and without laborious manual consolidation shortly before the audit. The platform view reduces the typical audit preparation sprint from two weeks to a few days and gives the ISB capacity for technical depth instead of document maintenance.
Personnel consequences: ISB, internal auditors, top management
The information security officer is the operational hub of the transition. He evaluates the eleven new controls, coordinates the implementation with IT, legal and specialist departments and leads the SoA. An appointment certificate with clearly defined tasks, authorities, time budget and reporting line is a prerequisite for reliable work. Without an appointment certificate, the formal sponsor function is missing in the audit, which can lead to complaints in clause 5.3 (roles, responsibilities and authorities). The appointment certificate, signed, filed, verifiable: This reflex distinguishes a well-maintained ISMS from an improvised one. If ordered externally, the certificate becomes part of the service contract and is kept in version form.
Internal auditors need training on the 2022 version because the checklists change. The training should take place before phase 3 so that the internal audit is based on the new standard. Top management is also affected: The management assessment according to clause 9.3 must be adjusted and the release of the updated SoA must be formally documented. A meeting with minutes and a resolution is sufficient, provided that the content of the resolution refers to the transitional measures and documents the allocation of resources.
If there is no capacity internally, the ISB function is outsourced. CIVAC is a compliance platform and officer-as-a-service: Licence the workspace for your internal officers, or have our officers order it. The external ISB takes over the operational management of the transition; the ultimate responsibility remains with the management in accordance with Section 13 OWiG. A reporting line to management is kept in writing at least quarterly, with the status of measures, risks and recommendations. In the workspace, the activity report is generated from the data that has already been maintained, and the ISB provides the technical assessment. The reporting line is therefore not dependent on individual people or Excel templates, but is anchored structurally.
Interaction with NIS-2, GDPR and other regulations
In practice, ISO/IEC 27001:2022 is increasingly being interlinked with other regulations. NIS-2 requires risk management for affected companies in accordance with Article 21 of the NIS-2 Directive, which is largely based on an ISMS. Anyone who is 27001:2022 certified meets the NIS 2 requirements for risk management, supply chain security, incident handling and business continuity with manageable additional effort. The 24-hour early warning and 72-hour follow-up notification for NIS-2 incidents complement, but do not replace, the ISMS incident process. Deadline expires as soon as we become aware of it: The reporting path must therefore be technically and organizationally tested, with a representation arrangement and a defined escalation path to management.
The GDPR requires appropriate technical and organisational measures in accordance with Article 32. A certified ISMS is a strong indication, but not automatically sufficient because the GDPR is based on specific processing activities. The eleven new controls (in particular A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention) have direct GDPR relevance. According to Art. 33 GDPR, data breaches must be reported within 72 hours; the ISMS incident process should also reflect the GDPR reporting path.
Industry-specific regulations complement the picture: KRITIS sectors with BSI KRITIS regulation, DORA for financial service providers, the German IT Security Act 2.0 and the EU Cyber Resilience Act for networked products. Anyone who maintains ISO 27001:2022, NIS-2, GDPR and industry-specific requirements in a single compliance workspace will have consistent files in the audit. If you keep each standard in its own file folder, you multiply the maintenance effort and the risk of inconsistencies. The cross-references between the standards can be maintained much more cost-effectively in a single file structure without losing any technical depth. A single update of a policy is effective in ISO 27001, NIS-2 and GDPR at the same time, provided the link is set correctly.
Reduce effort: platform view instead of file folders
The ISO/IEC 27001:2022 itself does not make the transition more complicated; the effort arises from maintaining documents in Word, Excel and SharePoint. Three pain points appear in almost every transition project: the manual mapping table 2013 to 2022, the inconsistency between SoA and risk register and the lack of versioning of guidelines. The auditor immediately recognises these pain points because they lead to questions that would not arise in a properly maintained system. Changing the certifier also becomes easier because the files do not have to be prepared first.
The CIVAC workspace covers ISO/IEC 27001:2022 with a structured module: 93 controls as a template, each with status, person responsible, measure, risk link and evidence storage. SoA, risk register, action plan and audit plan are linked views of the same data set. Version statuses are maintained automatically, escalation deadlines are reminiscent of action deadlines, and EU data residency is standard. The 490 ready-to-use audit templates cover internal audit programs, management review, incident documentation and transition mapping. For existing customers with maintained 2013 documentation, there is an import path that takes over the old content in a structured manner and creates the mapping sheet in one step. The appointment certificate, signed, filed, verifiable: The auditor calls, the evidence is ready.
Operationally, this means: Anyone who uses the workspace can complete the transition in six months instead of nine because the mapping table and the SoA do not have to be maintained manually. The internal audit uses checklists directly from the workspace, the ISB activity report to the management is generated from the existing data. Turn reading into a mandate.: The fastest way to a clean 2022 file situation is to consolidate it into a single platform.
Turn reading into an assignment
If you have the transition ahead of you, three questions are crucial: by when does the transition audit have to be completed, what capacity does your ISB have for implementation, and what is your current documentation quality. The action plan results from these three answers. If you have not yet ordered an ISB, clarify this question first. Anyone who has an ISB who cannot additionally bear the transition costs should clarify the question of temporary support. An honest self-assessment in this phase saves the frustration of accelerated audit preparation later.
CIVAC is a compliance platform and officer-as-a-service. This means: Licence the workspace for your internal representatives, or have our representatives order it. In the workspace model you get the ISO/IEC 27001:2022 module with 93 controls, SoA generator, risk register, action plan and 490 audit templates. In the officer model, an appointed external ISB with certified qualifications takes over operational control. The first order is placed in two working days, instead of two to six weeks in the classic market. The reporting line to management is contractually secured.
Both models can be combined: workspace for ongoing maintenance, external ISB for the transition phase. If you would like an initial assessment of whether your ISMS will last until October 2026, write to info@civac.de or use the contact form on civac.de. You will receive an initial evaluation with a model recommendation, effort estimate and order path within two working days. Compare the contents with our Transition letter for the October 2026 deadline. Turn reading into a mandate.: The fastest way to a clean 2022 file situation is a robust order, supported by an ISB with a mandate, workspace and a clear transition plan until October 2026.
FAQ
By when does the transition to ISO 27001:2022 have to be completed?
According to the IAF resolution, the transition period ends on October 31, 2026. Anyone who has not successfully switched to the new version by this deadline will lose their certification. In practical terms, this means: The transition audit should take place by mid-2026 at the latest, with a safety buffer for possible improvements. Anyone who starts later does not shorten the minimum technical duration, but rather increases the risk of missing the deadline.
How many controls does the new version have?
ISO/IEC 27001:2022 contains 93 controls in four subject groups: organisational (A.5), personal (A.6), physical (A.7) and technological (A.8). The previous version from 2013 had 114 controls in fourteen sections. Despite the lower number, the content has largely been retained, it has been summarized and supplemented by eleven new controls that address current threat topics such as cloud, threat intelligence and secure coding.
Which controls are new?
Eleven controls are new: A.5.7 Threat Intelligence, A.5.23 Cloud Security, A.5.30 ICT Readiness for Business Continuity, A.7.4 Physical Security Monitoring, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention, A.8.16 Monitoring Activities, A.8.23 Web Filtering and A.8.28 Secure coding. They reflect current threat situations, cloud realities and increased business continuity requirements and must be addressed in the SoA without exception.
Does the Statement of Applicability have to be created from scratch?
In fact, yes, because the control numbering changes. In terms of content, the old SoA is transferred to the new structure using a mapping table, supplemented by the eleven new controls and the link to the risk register. Top management must formally approve the updated SoA. The mapping is managed automatically in the CIVAC workspace and linked to the risk register.
How complex is the transition for a medium-sized company?
Six to nine months are realistic, including delta analysis, implementation of measures, internal audit round and transition audit by the certification body. With clean 2013 documentation and a low proportion of new controls that have not yet been implemented, the effort is reduced. Anyone who maintains Word and Excel documentation should tend to plan for the upper range. Workspace-based companies often do it in six months.
What happens if the deadline is not met?
The certificate expires on October 31, 2026. Re-certification then requires a full initial audit after 2022, not just a transition audit. For many clients, especially in the public sector, in the financial sector and in KRITIS areas, certification is a prerequisite for awarding a contract. A gap in the certificate can therefore have direct economic consequences.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.